Extradited Russian Hacker Faces Charges Over Excel Malware Campaign That Infected Thousands

4 hours ago 9

Swati KhandelwalSep 02, 2026Malware / Cybercrime

The U.S. Department of Justice (DoJ) has charged a Russian national, extradited from Cyprus on August 28, with using roughly 255 fake accounts on a freelance platform to send malware-laced Excel attachments to about 80,000 of its users in 2016 and 2017.

Searzhudin Tamirlanovich Aktulaev, 40, was arrested in Cyprus in May 2025, the U.S. Attorney's Office for the Northern District of California said in a press release. He made his initial appearance in federal court in San Francisco on August 31 and was remanded to federal custody.

The indictment, filed on June 1, 2021, and unsealed the same day as his appearance, describes the platform only as "a well-known freelance employment technology company" based in the Northern District of California.

Thousands of computers infected with TVRAT, one of two malware types named in the indictment, were calling back to a command-and-control (C2) domain hosted in the U.S., with approximately half of the victims located in the country, many of them in the district.

A shared document in the email account used in the scheme contained e-commerce login credentials and personally identifiable information (PII) for hundreds of victims.

Aktulaev is charged with conspiracy to commit wire fraud; transmission of a program, information, code, or command to cause damage to protected computers; conspiracy to commit computer fraud; unauthorized access to a protected computer to obtain information for financial gain and to obtain value; and aggravated identity theft.

Cybersecurity

The indictment alleges that from at least June 2016 through November 2017, the messages carried Excel attachments that prompted recipients to run a macro. The macro then downloaded malware from the internet.

The malware came in two types:

  • a variant of TVRAT, a TeamViewer remote access trojan (RAT) also known as TVSPY or TeamSpy, and
  • DarkVNC, both of which gave the operators remote control of the infected computer.

Both sent stolen data to the C2 server, from which it was collected and used by Aktulaev and his co-conspirators to commit fraud or other criminal activity, the DoJ said.

The DoJ's release says TVRAT exploits a vulnerability in TeamViewer. Russian cybersecurity vendor Kaspersky used the same term in its March 2013 report on TeamSpy, stating that the malicious module "uses a vulnerability in TeamViewer v6 known as Dll-hijacking."

"We have no evidence to assume a vulnerability of our software," a TeamViewer spokesman told Security Affairs in February 2017.

Avast, which analyzed a TeamSpy sample spread via Excel macros in April 2017, said the macro fetched a password-protected installer that bundles legitimate, digitally signed TeamViewer binaries with a malicious msimg32.dll.

The library is loaded in place of the genuine Windows dynamic-link library (DLL) via DLL search order hijacking, which Avast said is "a clever technique" because checking the main executable's signature reveals nothing suspicious.

Once loaded, the library hooks nearly 50 Windows Application Programming Interfaces (APIs) to prevent the TeamViewer window and its dialogs from being displayed to the victim. The infected machine then reports its TeamViewer ID to a C2 server. That ID, together with a preset password, is enough for the operators to connect to the computer remotely, Avast said.

DarkVNC, for its part, is a hidden virtual network computing (hVNC) utility that was first advertised on the Exploit forum on November 24, 2016, eSentire said in a February 2024 analysis.

Cybersecurity

The tool creates a concealed desktop on the infected machine for the operator to control. Microsoft has blocked Visual Basic for Applications (VBA) macros by default since 2022 in Office files obtained from the internet on Windows devices, the delivery step this campaign relied on.

Aktulaev has denied guilt and said he was unaware of the U.S. charges, according to statements from the Russian Embassy in Nicosia, as reported by RIA Novosti and TASS earlier this year.

The DoJ noted that the indictment contains allegations only and that Aktulaev is presumed innocent unless and until proven guilty.

The development comes as job-hunting and freelancing sites remain a recurring lure for state-sponsored actors, with ESET saying in February 2025 that North Korean hackers were using the same freelance-platform lure against software developers.

Last month, fake-recruiter campaigns were documented by Check Point Research, which said a Lazarus Group wave paired fake job offers with a remote-access backdoor, and by the Computer Emergency Response Team of Ukraine (CERT-UA), which said a Sandworm-linked cluster was contacting candidates through job-site chat before pushing a virtual private network (VPN) client that can run commands.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Read Entire Article